Research

Watch · narrated whiteboard episodesL3

Embedding and Retrieval Security: When the Vector Store Leaks and Lies

Embeddings are treated as opaque numbers, but they are near-invertible and attacker-manipulable, and the retrieval layer is both a confidentiality leak and an injection vector. This threat lab measures text-embedding inversion, nearest-neighbor and cross-tenant leakage, retrieval corruption by neighborhood poisoning, and approximate-index abuse for denial and eviction — each paired with a hardening. Grounded in the primary embedding-inversion and vector-index literature.

Murali Chillakuru·5 episodes
  1. 13 min Episode 1Embeddings Are Not Anonymized: Text-Embedding Inversion and How Much a Vector RevealsA moderator and an expert dismantle the assumption that a text embedding is an opaque, anonymous representation — showing how inversion attacks reconstruct the original text from vectors, and what that means for systems that store them.
  2. 12 min Episode 2Cross-Tenant and Neighbor Leakage: The Similarity Oracle and Multi-Tenant Isolation FailuresA moderator and an expert examine how a nearest-neighbor search becomes a disclosure oracle — and how shared vector indexes fail to separate tenants when crafted queries can reach across boundaries.
  3. 11 min Episode 3Retrieval Corruption: The Geometry of Poisoning a Neighborhood to Dominate a QueryA moderator and an expert examine how an attacker crafts a single document to sit closest to a target query in embedding space, guaranteeing it gets retrieved and its content reaches the language model.
  4. 12 min Episode 4Index-Level Attacks: Exploiting Approximate-Index Knobs for Denial and EvictionA moderator and an expert examine how approximate nearest-neighbor index parameters are exploitable attack surfaces — enabling denial of retrieval, eviction of competitors, and silent cost amplification.
  5. 14 min Episode 5Hardening Retrieval: Per-Tenant Indexes, Embedding-Space Access Control, and ProvenanceA moderator and an expert build a defensive blueprint for the vector store — treating it as a security boundary that must survive inversion, oracle, corruption, and index-level attacks.